Umbra Wiki cve cve/CVE-2022-43769
Back to wiki

CVE-2022-43769 — Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

provenance: imported · CVE: CVE-2022-43769

CVE-2022-43769: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Hitachi Vantara
Product Pentaho Business Analytics (BA) Server
Date added 2025-03-03
Due date 2025-03-24
Ransomware campaign use Unknown

Description

Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes

https://support.pentaho.com/hc/en-us/articles/14455561548301--Resolved-Pentaho-BA-Server-Failure-to-Sanitize-Special-Elements-into-a-Different-Plane-Special-Element-Injection-Versions-before-9-4-0-1-and-9-3-0-2-including-8-3-x-Impacted-CVE-2022-43769 ; https://nvd.nist.gov/vuln/detail/CVE-2022-43769

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-43769
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog